DSACMS / metrics

Experimentations in Open Source Repository Metrics
https://dsacms.github.io/metrics/
Other
6 stars 2 forks source link

Add GitHub CodeQL #121

Closed IsaacMilarky closed 3 months ago

IsaacMilarky commented 3 months ago

Add GitHub CodeQL

Problem

OSSF Scorecard currently gives us a 0 in the SAST category. https://github.com/DSACMS/metrics/security/code-scanning/31

Solution

Add GitHub CodeQL scanning to every commit to satisfy OSSF scorecard requirements.

Result

Add codeql.yml to workflows.